CVE-2026-14180
Last modified
CVE-2026-14180 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags.
Description
A flaw was found in the ChunkReader component of the Undertow HTTP server, which is used by WildFly and JBoss EAP to handle chunked transfer encoding. The issue occurs because the parser uses a single internal variable to store both the remaining chunk size and state flags. By sending a specially crafted request with an extremely large chunk size, an attacker can cause these values to overlap, tricking the parser into thinking a request has finished prematurely. This can allow a second, "smuggled" request to be processed out of sync, potentially bypassing security controls.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat build of Apache Camel for Spring Boot 4 | All versions |
| Red Hat | Red Hat build of Apache Camel - HawtIO 4 | All versions |
| Red Hat | Red Hat Data Grid 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 10 | All versions |
| Red Hat | Red Hat Enterprise Linux 8 | All versions |
| Red Hat | Red Hat Enterprise Linux 9 | All versions |
| Red Hat | Red Hat Fuse 7 | All versions |
| Red Hat | Red Hat JBoss Enterprise Application Platform 7 | All versions |
| Red Hat | Red Hat JBoss Enterprise Application Platform 8 | All versions |
| Red Hat | Red Hat JBoss Enterprise Application Platform Expansion Pack | All versions |
| Red Hat | Red Hat Single Sign-On 7 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Received
Frequently Asked Questions
What is CVE-2026-14180?
How severe is CVE-2026-14180?
How do I fix CVE-2026-14180?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-14170Rejected reason: This CVE ID has been rejected or withdrawn …
- CVE-2026-14171An unauthenticated remote attacker can abuse the improper va…6.1
- CVE-2026-14172Rapid7 InsightVM, Nexpose, and the Insight Agent execute dis…7.8
- CVE-2026-14175Unrestricted upload of file with dangerous type vulnerabilit…9.8
- CVE-2026-14178openGauss 在处理带 NLS 参数的 to_timestamp 调用时,to_timestamp_with_fm…5.9
- CVE-2026-1418A security vulnerability has been detected in GPAC up to 2.4…7.8
- CVE-2026-14181@fastify/middie versions 9.1.0 through 9.3.2 fail to guard t…7.5
- CVE-2026-14183The Classified Listing WordPress plugin before 5.3.9 does n…4.3
- CVE-2026-14184The Academy LMS WordPress plugin before 3.8.1 does not verif…5.4
- CVE-2026-14185The WPBot WordPress plugin before 8.2.0 does not perform a …4.3
- CVE-2026-14188The Easy Appointments WordPress plugin before 3.12.28 does n…2.7
- CVE-2026-14189The WPBot WordPress plugin before 8.5.2 does not validate a…3.8
Are you affected by CVE-2026-14180?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
